Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6302-1 | starlette security update |
Github GHSA |
GHSA-86qp-5c8j-p5mr | Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks |
Tue, 16 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Encode
Encode starlette |
|
| CPEs | cpe:2.3:a:encode:starlette:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Encode
Encode starlette |
Thu, 28 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1289 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 27 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kludex
Kludex starlette |
|
| Vendors & Products |
Kludex
Kludex starlette |
Tue, 26 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values. | |
| Title | Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks | |
| Weaknesses | CWE-444 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-30T01:48:17.511Z
Reserved: 2026-05-22T18:47:27.755Z
Link: CVE-2026-48710
Updated: 2026-06-30T01:48:17.511Z
Status : Modified
Published: 2026-05-26T22:16:44.020
Modified: 2026-06-17T10:55:13.440
Link: CVE-2026-48710
OpenCVE Enrichment
Updated: 2026-05-28T04:45:07Z
Debian DSA
Github GHSA